CVE-2026-87634
massUse-after-free in Chrome WebPackaging allows potential sandbox-escaping code execution
CVE-2026-87634 is a use-after-free vulnerability in the WebPackaging component of Google Chrome, triggerable by a remote attacker who persuades a user to open a crafted HTML page. If successfully exploited, the attacker could potentially execute arbitrary code outside of the browser's sandbox, although Google's Chromium team rates the issue as Low severity despite the critical-sounding 9.6 CVSS score. The flaw affects Google Chrome versions prior to 153.0.8010.36, and given Chrome's enormous install base, this potentially touches billions of users until auto-updates complete. There is currently no evidence of exploitation: the bug is not in CISA's Known Exploited Vulnerabilities catalog, EPSS assigns only a 0.3% probability of exploitation within 30 days, and no public proof-of-concept is known. Patched builds are already shipping through Chrome's auto-update mechanism, so the vulnerable population should shrink quickly.
What to do: Update Google Chrome to 153.0.8010.36 or later; the fastest path is to force a check via Settings > About Chrome, which applies the update and relaunches the browser. Administrators should verify installed browser versions through endpoint management or EDR telemetry and confirm auto-update is enabled across the fleet. Given the Low severity rating, absence of a public PoC, and no known exploitation, standard patch-cadence handling is reasonable rather than emergency remediation.
| Google Chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.